Read this first
There is roughly one page of genuine narrative prose about Supplier Risk in the available SAP material. Almost everything else is a chapter title or a support-article title. This guide keeps those confidence levels apart rather than smoothing them into a false procedure, because in ICM a confident wrong instruction is more expensive than an honest gap.
Two consequences shape everything below. First, no Supplier Risk site configuration parameter is documented anywhere — despite ICM carrying a category literally named Supplier Risk Parameters. Any Application.SupplierRisk.* string you see in a public guide is invented. Second, where two sources disagree, both sides are printed and neither is picked. Verify against the tenant.
A guide that papers over the gaps in Supplier Risk will get someone into trouble in ICM. The gaps are part of the design input.
What Supplier Risk is, and where its boundary sits
Supplier Risk identifies, assesses, monitors and mitigates supplier risk. It is the only solution in the Supplier Management family that does risk monitoring and control-based risk assessment, and the architecture column calls it standalone — not a module of SLP. Its stated purpose has two modes, and they map onto the two halves of the product.
| Purpose | Capability |
|---|---|
| Monitor the potential risk of current suppliers | Risk exposure, scores, alerts, dashboards |
| Assess the risk of new suppliers before committing to them | Control-Based Engagement Risk Assessment |
Five capability headlines are attributed to Supplier Risk: risk due diligence, proactive risk monitoring, collaborative risk disposition, brand reputation protection, and control-based engagement risk assessment. Note the last one is named in a single source file — and it is the capability an entire workstream usually rests on. Scope it with that in mind.
Four administration surfaces, not one
Configuration is spread across SM Administration (BTP), Risk administration where provider credentials live, Enrichment Administration which may itself need enabling, and ICM, which carries a Supplier Risk Parameters category whose contents are undocumented. “Where do I configure this?” is a real question on this product, and answering it wrong costs a sprint.
Add two more: the Unified Vendor Model question — whether adding Supplier Risk to a legacy site triggers a UVM migration — has no published answer, so ask SAP in writing before you plan a data migration you may or may not need. And ICM's revert model only rolls back the most recent deployment, which is why one package per logical change is a discipline, not a preference.
Prerequisites and pre-configuration decisions
Entitlement comes first — if Supplier Management or Supplier Risk is not visible on the site, check entitlement before you check configuration (3290213). Then activation is a process, not a switch: it is a named process with its own failure article (3644870), filed as a Problem. Budget calendar time and raise it early.
Every project comes from a template, and master data comes before templates: import required data → configure templates → customize notifications → configure default dashboards. Commodity codes, regions and departments are shared across all Strategic Sourcing solutions, so a template referencing master data that is not loaded simply will not behave.
The three Risk-specific configuration steps — as close to a build order as the source gets — are: configure Risk Exposure, configure control-based risk assessment projects, import supplier risk data. Section 13 expands that with the prerequisites and failure modes the source states elsewhere.
One-way doors: decide these before production
Three enablement decisions change what the UI can do, and none is documented as reversible. A fourth is a hard prerequisite that will stop you dead. These belong in a pre-production decision workshop, not in a change ticket.
| Action | Documented consequence | KBA |
|---|---|---|
| Enabling control-based Engagement Requests | Not a toggle. It runs a scheduled task, MigrateSRNewProjectsTemplatesTask, and that task can fail. Nothing documents what the task changes. | 3666311 |
| Feature ARI-4598 — advanced send assessments | You can no longer send risk assessments individually. | 3183689 |
| Finding and Event Collaboration (FEC) | The Create Issue option disappears from Engagement Requests. By design, and one-way. | 3605362 |
| Prerequisite: FEC requires Sourcing SSO | “No SAP Ariba Sourcing systems with valid single sign-on setups available” is the verbatim error when it is missing. | 3580370 |
Three more at lower severity
| Action | Consequence |
|---|---|
| Template Upgrade on Engagement Request projects | Can end in status Upgrade Failed (3303389). Rehearse in a test realm. |
| ICM package deployment | Only the most recent deployment can be reverted. There is no full version management — one package per logical change. |
| FEC template customization | Filed as a Known Error (3748559) — the only Known Error in the entire Supplier Risk article set. |
There is no rollback procedure for Supplier Risk configuration anywhere beyond ICM's single-deployment revert. Read notes 3183689, 3605362, 3666311 and 3580370 before enabling anything, and write the decision down with a name against it.
Groups, and the cost dimension nobody mentions
Three different group lists exist in the source and they disagree with each other. Only two names survive all three: Supplier Manager and Supplier Risk Manager. Take group names from the Strategic Sourcing and Supplier Management Group Descriptions guide, never from a summary table — including any in this guide.
The genuinely non-obvious insight: in Supplier Risk, group membership drives chargeability. Two groups the summary lists never mention — SM ERP Administrator and SM Ops Administrator — make their members chargeable users. Check the Group Licensing Reference before you assign either, and export usage metrics periodically.
Two Risk-specific permission facts: the User Matrix reaches into Supplier Risk and governs Engagement Request approvals and Issues (3433355) — check it first when approvals do not resolve. And approver resolution can surface a group name instead of a person (3675814); decide in UAT whether audit accepts that.
| Question | KBA |
|---|---|
| What Supplier Risk users count as a licensed user? | 3361571 |
| Why are members of the SM ERP Administrator and SM Ops Administrator groups now chargeable users? | 3269932 |
| What do the roles of Supplier Risk allow users to do? | 3186275 |
| User Metrics Report did not show if a user was active or inactive | 3190403 |
| Roles and permissions required for supplier-profile navigation in Joule | 3719864 |
Risk exposure: four bullets, and what they are not
The entire narrative documentation of risk exposure configuration is four bullets: define the risk categories relevant to the organization; configure the weight of each category; select risk data sources (content providers); set alert thresholds per risk level. No parameter names, no scale, no formula, no defaults, no UI path.
Read them for what they are: a design agenda, not a procedure. They map cleanly onto four workshops — category set, weighting model, provider selection, threshold and notification policy. What they cannot do is tell you where to click. Plan a tenant walkthrough with the client's administrator as an explicit project task, not an afterthought.
Before designing a single category, establish which scoring regime the tenant runs — Custom Risk Categories or Legacy Scoring (3721985). SAP publishes a how-to for checking, which means it is a thing to determine rather than assume. Combined with a chapter on Managing Legacy Risk Assessment Projects, that is two independent signals of a generational split inside the product. On a brownfield tenant, that is a week-one discovery question.
The scoring vocabulary exists; none of it is defined
| Term | Where it appears | KBA |
|---|---|---|
| Risk Exposure (as a calculated value) | How is the Risk Exposure calculated? | 3183969 |
| Overall inherent risk score | Showing N/A in Supplier 360 / not updated or Not Applicable | 3495126, 3736860 |
| Inherent Risk score on Engagement Requests | No Inherent Risk score / incorrect Inherent Risk values | 3551434, 3244929 |
| Residual Risk Domain | Residual Risk Domain not calculated | 3566091 |
| Risk domain as a scoring axis | Calculate inherent risk for ERs by risk domain | 3189134 |
| Custom Risk Categories vs. Legacy Scoring | How to Check Scoring Type in Supplier Risk | 3721985 |
Content providers are a contract question first
D&B, EcoVadis and Bureau van Dijk appear in the corpus as providers whose data feeds exposure scores. The failure that eats the most time is not an Ariba one: D&B registration failing with error code (00041) resolves against the client's own D&B account authorisation (3684395). Confirm the contracts and credentials exist before you schedule the integration test.
Credentials are entered in a Risk administration area (3360417), and Enrichment Administration is its own surface that may need enabling (3736855) — which is why “I can't find where to put the credentials” is a real, documented symptom rather than user error. When provider scores are missing from the overall score, check aggregation separately from provider connectivity.
Which suppliers get monitored: three populations, not one
Everyone starts by assuming “the suppliers in Risk” is one set. It is at least three, they are managed differently, and a supplier can be in one and not another. The selection mechanism itself is not documented at all — but the failure catalogue proves the scope goes wrong in independent ways.
| Population | Symptom when it is wrong | KBAs |
|---|---|---|
| Visible in Supplier Risk at all | Suppliers not visible in Supplier Risk; unable to search suppliers in Supplier Risk | 3182921, 3179441 |
| Followed — which drives the Alert Feed | Alerts in the Alert Feed for suppliers you unfollowed; is there a report to identify followed suppliers? | 3440209, 3638969 |
| Selectable when creating an Engagement Request | Different suppliers returned from search when creating an Engagement Request | 3734396 |
| Third parties — a fourth object class | Standard fields for third parties within Supplier Risk; suppliers missing from the Risk Map | 3420517, 3571310 |
Design the test plan to assert each population separately, and expect at least one to surprise you in UAT. If the client's risk scope includes non-supplier third parties — agents, distributors, JV partners — third parties is a fourth object class with its own standard fields, and the corpus says nothing else about it. Promise nothing there without reading 3420517.
Control-based engagement risk assessment
This is the pre-commitment half of the product: an assessment based on predefined controls, generating assessment projects with an approval workflow. Enablement is not a toggle — it runs MigrateSRNewProjectsTemplatesTask, and that task fails often enough to have its own article. Assign someone to watch it.
The object model has to be recovered from failure articles: controls have a type and an importable status (3722166), controls are evaluated at ER creation and can fail to trigger (3528588), and control assessments differ from assessment versions — the two can show different responses (3748213). How a control is authored, and what fields it has, is never stated.
Templates carry the rest of the risk. Template Upgrade can end in Upgrade Failed (3303389) — rehearse it in a test realm. Task order in the ER UI is known to drift from the template (3605435), so verify after every upgrade. And FEC template customization is filed as a Known Error (3748559), the only one in the whole Supplier Risk set.
APIs and imports: two blockers and a silent corruption
| API fact | KBA | Date |
|---|---|---|
| Risk Category Information API for Supplier Risk Exposure exists | 3184142 | Apr 2022 |
| Behaviour of supplier custom fields when using that API | 3721402 | Mar 2026 |
| ⚠ The Supplier Risk Engagement API does not support bulk extraction of all workspaces | 3705132 | Mar 2026 |
| ⚠ smVendorId in GET /questionnaires returns a Workspace ID for control-type assessments | 3757372 | May 2026 |
| 400 – Bad Request on the Supplier Risk Engagements API | 3341615 | Jun 2023 |
| POST /vendordatarequests returns suppliers when only certificate status changes; no response filtering | 3753022 | May 2026 |
The two flagged rows are design blockers, and both are recent. No bulk extraction of Engagement workspaces means “export all our risk assessments to the data lake” needs a different design entirely. And smVendorId returning a Workspace ID for control-type assessments is the kind of field-semantics surprise that silently corrupts a downstream join — assert on the value type before you key anything off it.
Imports relevant to Risk
| Import | What can go wrong | KBA |
|---|---|---|
| Risk External IDs file | “Could not find smVendorId for erpVendorId=XXXXX” — clean the vendor-key mapping first | 3346928 |
| Control status import | Engagement-type control status does not change after import | 3722166 |
| Supplier Risk Data Import | Carries risk data and the master data assessment projects need. No file layout is published | — |
| Supplier Data Import (SM Administration) | Fails with a Unique Constraint Violation | 3529477 |
| Any CSV import | Leading zeroes removed — silent corruption of exactly the vendor keys Risk joins on | 3190123 |
| Import verification | Download the import summary under SM Administration and reconcile counts | 3274930 |
Never treat an import success message as verification. Download the import summary and reconcile record counts. The leading-zeroes behaviour is worth a dedicated pre-import check, because it corrupts exactly the fields the Risk External IDs import keys on.
Symptom → layer
With one confirmed defect in ninety-three articles, when Supplier Risk misbehaves the answer is almost never a bug. Check enablement, scope, template and provider credentials before you say “SAP bug” — and route the case to the right component the first time.
| Symptom | Look at |
|---|---|
| A supplier doesn't appear in Supplier Risk at all | Evaluated-supplier scope, then search (3182921, 3179441) |
| Different suppliers appear when creating an Engagement Request | A different population from Risk visibility (3734396) |
| Alerts stopped firing, or fire for the wrong suppliers | Alert configuration, then the follow/unfollow model (3184092, 3440209) |
| Risk score shows N/A or “Not Applicable” | Scoring regime first — Custom vs. Legacy — then provider data (3721985, 3495126) |
| Residual risk not calculating | Residual Risk Domain (3566091) |
| Engagement Request has no Inherent Risk score | ER-level scoring (3551434, 3244929) |
| D&B or EcoVadis scores absent from the overall score | Provider integration and score aggregation (3386868, 3684395) |
| D&B registration fails with error code (00041) | The client's D&B account authorisation — not Ariba configuration (3684395) |
| Can't find where to enter provider credentials | Risk administration / Enrichment Administration enablement (3360417, 3736855) |
| Engagement Request stuck in Edit, or cannot be cancelled | ER lifecycle state (3591797, 3309170, 3713722) |
| Risk Controls didn't trigger on ER creation | Control configuration (3528588) |
| “Send Assessments” task stuck | The task, then bulk behaviour, then ARI-4598 (3455392, 3515411, 3183689) |
| Approval on an ER resolves to nobody or the wrong approver | User Matrix first, then the approval flow (3433355, 3402199) |
| Create Issue option disappeared | FEC was enabled — by design, and one-way (3605362) |
| Risk emails arrive branded as Sourcing notifications | Risk reuses the Sourcing notification framework (3700262, 3318639) |
| Template Upgrade ends in “Upgrade Failed” | Upgrade eligibility and rehearsal (3303389, 3609058) |
| Risk exposure not visible in Guided Buying or Guided Sourcing | Per-surface configuration (3379973, 3640466) |
Build order, and what you see if you invert it
| # | Do this | What you see if you invert it |
|---|---|---|
| 1 | Confirm entitlement and run the activation process | Activation is a named process with its own failure article, not a switch (3290213, 3644870) |
| 2 | Determine the scoring regime — Custom Risk Categories or Legacy Scoring | The four-bullet exposure design presupposes custom categories; the wrong regime means redesigning (3721985) |
| 3 | Determine which generation of risk assessment projects is live | A whole chapter exists for legacy assessment projects, and neither generation is described |
| 4 | Make and record the one-way-door decisions | ARI-4598, FEC and control-based ER enablement have no documented way back |
| 5 | Establish Sourcing SSO before enabling FEC | “No SAP Ariba Sourcing systems with valid single sign-on setups available” (3580370) |
| 6 | Confirm provider contracts and credentials before testing enrichment | D&B registration fails on the client's provider account, not on your config (3684395) |
| 7 | Load shared master data, and groups before users | A template referencing master data that isn't loaded will not behave |
| 8 | Check the Group Licensing Reference before assigning admin groups | Membership makes users chargeable — a budget line, not a permission detail (3269932) |
| 9 | Clean the vendor-key mapping before the Risk External IDs import | “Could not find smVendorId for erpVendorId” (3346928) |
| 10 | Configure Risk Exposure — categories, weights, providers, thresholds | Otherwise scores read N/A and ERs carry no Inherent Risk (3495126, 3551434) |
| 11 | Define the evaluated-supplier scope — all three populations | Invisible, unsearchable, or a different set inside ER creation (3182921, 3734396) |
| 12 | Import Supplier Risk project templates | Every project comes from a template; read the import best-practice article first (3185077) |
| 13 | Import Supplier Risk Data, including assessment master data | The dependency is stated; the file layout is not documented anywhere |
| 14 | Configure Risk notifications separately from SLP notifications | Misconfiguration emits Sourcing-branded email from Risk (3700262, 3318639) |
| 15 | Test each output surface individually | Seven surfaces, nine independent “why isn't it showing” articles |
Configuration checklist
Before you configure, and before you go live
- Confirm Supplier Risk entitlement, and whether the client is on full Supplier Risk or base edition.
- Run the activation process early and treat it as lead time (3644870).
- Confirm the scoring regime and the assessment-project generation on the tenant.
- Decide and record ARI-4598, FEC and control-based ER enablement — read all four notes first.
- One ICM package per logical change; only the last deployment is revertible.
- Take group names from the Group Descriptions guide, not from summary tables.
- Check the Group Licensing Reference before assigning SM ERP Administrator or SM Ops Administrator.
- Validate that User Matrix assignments resolve on Engagement Requests before UAT (3433355).
- Run a tenant walkthrough of risk exposure — it substitutes for documentation that does not exist.
- Confirm the actual risk category set on the tenant; do not design from any summary table.
- Establish the risk data refresh frequency and tell the business what it is (3547822).
- Verify D&B / EcoVadis / BvD contracts and credentials before the integration test.
- Define all three supplier populations explicitly — visible, followed, ER-selectable — and test each.
- Decide whether third parties are in scope (3420517).
- Check every CSV for leading-zero corruption and reconcile the import summary (3190123, 3274930).
- Rehearse Engagement Request template upgrade in a test realm (3609058, 3303389).
- Remember modular questionnaires and certificate management enable together (3183117).
- Do not design a bulk export of Engagement workspaces — the API does not support it (3705132).
- Assert on the smVendorId value type before joining on it downstream (3757372).
Glossary
| Term | Meaning |
|---|---|
| Alert Feed | The alert surface in Supplier Risk, driven by a follow/unfollow model (3440209, 3638969). |
| ARI-4598 | Feature ID: enable advanced send assessments. Enabling it removes individual assessment sending. |
| base edition | SAP Ariba Supplier Risk, base edition — named twice in the source and never described. |
| BTP | SAP Business Technology Platform. Hosts SM Administration, Supplier Profile Summary and FEC. |
| BvD | Bureau van Dijk — a third-party content provider; credentials are entered in Risk administration (3360417). |
| Control / Risk Control | The predefined due-diligence object behind control-based assessment. Evaluated at ER creation; has a type and an importable status. |
| Control-Based Engagement Risk Assessment | An assessment run before committing to a supplier, based on predefined controls, generating assessment projects with an approval workflow. |
| Engagement Request (ER) | The project object that carries an inherent risk score, controls, tasks, approvals and issues. |
| FEC | Finding and Event Collaboration. Requires Sourcing SSO; enabling it removes Create Issue from ERs. |
| Finding vs. Issue | Two object names SAP has never reconciled. Establish on the tenant which one your client's process means. |
| MigrateSRNewProjectsTemplatesTask | The scheduled task that performs control-based ER enablement — and can fail (3666311). |
| Risk Exposure | The calculated continuous-monitoring value: categories, weights, provider data and alert thresholds. |
| smVendorId / erpVendorId | The vendor-key pair the Risk External IDs import joins on. Clean it before importing. |
One ambiguity SAP has never reconciled: Findings versus Issues. Both object names are in use, the new Findings feature has its own feature ID, and enabling FEC removes Create Issue. Settle on the tenant which one your client's process actually means before you write a process document around either.